Privacy Policy
Last updated: August 13, 2026
This policy explains what SlopStopper ("we," "us") collects when you use theslopstopper.com (the "Service"), why, and what choices you have.
Who we are
SlopStopper is operated by Xclusive Access LLC. You can reach us at support@xclusive-access.com with any question about this policy or your data.
What we collect, and why
Running a scan without connecting GitHub. If you paste a URL or upload code, we process what you gave us to produce a scan result and, if you're on the free trial, set a signed cookie that just counts how many free agent-test runs you've used — it doesn't identify you. Your scan history in that flow lives only in your own browser's local storage; it's never sent to our servers.
Connecting a GitHub repo. There's no separate signup — installing our GitHub App and connecting a repo is what creates your account. We store your GitHub user ID and username. We don't collect a password or ask for your email directly (GitHub doesn't hand that to us unless you've made it public).
Repository content. To scan a connected repo, we fetch its files from GitHub via the permissions you grant when installing the app. We don't keep a permanent copy of your source code — each scan reads what it needs and discards it. What we do keep, tied to the repo, is the scan's result: the readiness score and a summary of findings, so you can see history and so we don't re-flag something you've already dismissed.
AI-generated fixes and automated testing. If you use the paid "open a PR with AI fixes" or "agent test" features, the relevant file contents or a description of your app's flows are sent to Anthropic's Claude API to generate the suggested fix or drive the test. This is the one place your code leaves GitHub-and-us and goes to a third party — it only happens when you actively use one of these features, never on a plain scan.
A live URL you give us. If you provide a deployed URL (either for a one-off scan, or saved so it's checked automatically on every push), our scanner requests pages from it the way a normal visitor or crawler would, to check things like broken links, missing security headers, and accessibility issues.
Billing. If you subscribe to a paid plan, Stripe handles your payment details directly — we never see or store your card number. We keep only your Stripe customer and subscription IDs and a record of what billable actions you've used, so we can enforce your plan's limits.
GitHub webhook events. For repos with our GitHub App installed, we receive push, pull-request, and comment events from GitHub so automatic scans and the AI-fix Q&A flow can run without you visiting the site.
Cookies
We use a small number of functional cookies: one to keep you signed in after connecting GitHub, one to track free-trial usage (see above), and one used during the GitHub App install flow. None of these are advertising or cross-site tracking cookies, and we don't run any third-party analytics or ad-tracking scripts on the site.
Who we share data with
To actually run the Service, some data necessarily passes through:
- GitHub — to read repository content and open pull requests, when you connect a repo.
- Anthropic — to generate AI fix suggestions and drive agent-based testing, only when you use those features.
- Stripe — to process payments for paid plans.
- Vercel — our hosting provider, which runs the Service's servers.
- Neon — our database provider, which stores account and scan-result data.
We don't sell your data, and we don't share it with anyone else for their own marketing purposes.
How long we keep it
Scan results and account data for a connected repo are kept as long as the account exists — mainly so history and "already dismissed" state keep working. Uninstalling the GitHub App stops us from scanning the repo further, but doesn't automatically erase past scan history; email us if you'd like it deleted and we will. Unauthenticated, browser-local scan history is entirely under your control — clearing your browser's storage removes it.
Your rights
You can ask us what we have on you, ask us to correct it, or ask us to delete it, by emailing support@xclusive-access.com. Depending on where you live, you may have additional rights under laws like the GDPR or CCPA.
Children
The Service isn't directed at children, and we don't knowingly collect data from anyone under 13.
Security
We take reasonable technical measures to protect your data, but — fittingly, given what this product scans for — no service can guarantee perfect security. If we become aware of a breach affecting your data, we'll notify you.
Changes to this policy
If this policy changes in a material way, we'll update the date at the top of this page and, for significant changes, let existing users know directly.
Contact
Questions about this policy or your data: support@xclusive-access.com.